rpm_decode_object_property of the file src/bacnet/rpm.c of the component ReadPropertyMultiple Service. This manipulation causes out-of-bounds read.This vulnerability appears as CVE-2026-41503. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.